Third-Party Security Manager

atGuild MortgageRemoteUS flagUnited StatesFull-timeCybersecurity / Security EngineerMid-levelSenior$94.9k – $136.1k/year

Posted 10 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Lead and enhance the organization's Third-Party Risk Management (TPRM) program.

• Develop, sustain, and continually refine TPRM frameworks, policies, standards, and procedures.

• Establish risk-based processes for onboarding, reviewing, monitoring, and offboarding third parties.

• Define methodologies for vendor risk assessments and criteria for risk scoring.

• Align third-party risk practices with standards such as NIST, SOC 2, ISO 27001, FFIEC, GLBA, PCI-DSS, as well as relevant privacy regulations.

• Conduct assessments of security, privacy, operational, compliance, and business continuity risks for vendors.

• Review vendor security documentation, which includes SOC reports, ISO certifications, penetration test reports, vulnerability management reports, security questionnaires, and continuity plans.

• Identify control gaps and coordinate remediation strategies with vendors and stakeholders.

• Evaluate dependencies on fourth-party providers and concentration risks.

• Maintain inventories of third-party relationships and their associated risk ratings.

• Develop processes for the continuous monitoring of critical and high-risk vendors.

• Monitor vendor security ratings, threat intelligence, breach activities, financial health, and compliance status.

• Track remediation efforts and facilitate regular vendor reviews and reassessments.

• Collaborate with Procurement, Legal, Privacy, Compliance, business owners, and Information Security during vendor selection and contract negotiations.

• Provide guidance on vendor risk to business leaders.

• Present findings and recommendations regarding vendor risk to leadership, risk committees, and executive management.

• Support internal and external audits concerning vendor management controls.

• Establish security and privacy contractual obligations in collaboration with Legal and Procurement.

• Review and suggest contract language related to security controls, data protection, breach notification, audit rights, business continuity, and regulatory compliance.

• Ensure that vendor agreements incorporate relevant security, privacy, and reporting obligations.

• Develop and maintain TPRM dashboards, KPIs, and executive reporting.

• Track assessment volumes, remediation progress, risk trends, and metrics of program maturity.

• Regularly report to Information Security leadership, Enterprise Risk Management, and audit committees.

• Support initiatives for risk quantification and business impact analysis.

• Mentor and guide less experienced professional contributors.


⛳️ Requirements

• Bachelor's Degree directly related to the position or equivalent is preferred.

• A minimum of five years of relevant experience is required.

• At least three years of supervisory or leadership experience is necessary.

• Excellent verbal and written communication skills are essential.

• Highly organized and detail-oriented approach is required.

• Ability to thrive in a fast-paced, metrics-driven environment.

• Proficiency in Microsoft Office Suite, including Word and Excel, Wiki, collaborative cloud-based tools, and third-party software applications.

• A strong commitment to company values is expected.

• Availability to work Monday through Friday during standard business hours.

• Travel requirements of 5% or less.

• Work is primarily sedentary, involving frequent use of a computer keyboard and mouse.

• Capability to learn new tasks, retain processes, maintain focus, complete tasks independently, and make timely decisions.

• Ability to adhere to and apply established process protocols in a timely manner.


🏝️ Benefits

• Medical insurance.

• Dental insurance.

• Vision insurance.

• Life insurance.

• AD&D insurance.

• LTD insurance.

• 401(k) with employer match.

• Competitive compensation.

• Pleasant work environment.

People also viewed

Agile Defense8 hours ago

Senior Security Architect

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer$150k – $155k/year
ApplyView job
Stripe9 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cambiar Education13 hours ago

Director, IT – Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $170k/year
ApplyView job
Docker, Inc13 hours ago

Senior Security Engineer – Offensive Security

GB flagUnited Kingdom, +4 more countriesFull-timeCybersecurity / Security Engineer€118.9k – €169.8k/year
ApplyView job
OpenZeppelin13 hours ago

Head of Information Security

Anywhere in the WorldFull-timeCybersecurity / Security Engineer
ApplyView job
Motive13 hours ago

Red Team Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$146k – C$190k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers